Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the server to send HTTP GET requests to arbitrary URLs.
Metrics
Affected Vendors & Products
References
History
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Blind SSRF in Legacy Co‑authoring Connection Methods of M‑Files Server | |
| First Time appeared |
M-files
M-files m-files Server |
|
| CPEs | cpe:2.3:a:m-files:m-files_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
M-files
M-files m-files Server |
|
| Metrics |
cvssV3_1
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Apr 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the server to send HTTP GET requests to arbitrary URLs. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: M-Files Corporation
Published: 2026-04-01T10:03:27.785Z
Updated: 2026-04-01T12:38:30.875Z
Reserved: 2026-01-14T07:38:43.377Z
Link: CVE-2026-0932
Updated: 2026-04-01T12:38:26.492Z
Status : Analyzed
Published: 2026-04-01T11:15:58.263
Modified: 2026-04-02T18:18:54.860
Link: CVE-2026-0932
No data.